CVE-2025-54905
published 2025-09-09CVE-2025-54905: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
PriorityP430high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.58%
44.0th percentile
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.101.25091314 | 16.101.25091314 |
| microsoft | microsoft_office_ltsc_for_mac_2024 | >= 16.0.0 < 16.101.25091314 | 16.101.25091314 |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5517.1000 | 16.0.5517.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20047 | 16.0.10417.20047 |
| microsoft | microsoft_word_2016 | >= 16.0.1 < 16.0.5517.1000 | 16.0.5517.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2021 | — | — |
| msrc | microsoft_office_ltsc_for_mac_2024 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Word Information Disclosure Vulnerability
vendor_msrc·2025-09-09·CVSS 7.1
CVE-2025-54905 [HIGH] CWE-822 Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability
Description: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Yes, the Preview Pane is an attack vector.
FAQ: Are the updates for Microsoft Office LTSC for Mac 2021 and 2024 currently available?
Yes. As of September 15, 2025, the security update for Microsoft Office LTSC for Mac 2021 and 2024 are available. Customers running Microsoft Office LTSC for Mac 2021 and 2024 should ensure the update is installed to be protected from this vulnerability.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious
GHSA
GHSA-f8jp-v63x-5qqw: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally
ghsa_unreviewed·2025-09-09
CVE-2025-54905 [HIGH] CWE-822 GHSA-f8jp-v63x-5qqw: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
No detection rules found.
No public exploits indexed.
2025-09-09
Published